Explained | EU fines Facebook parent company Meta record $1.3 billion over data transfer to US

Explained | EU fines Facebook parent company Meta record $1.3 billion over data transfer to US

Facebook and Meta

Facebook parent Meta was fined with a record amount of $1.3 billion (1.2 billion euros), on Monday (May 22). The fine was levied for the company’s failure to comply with a warning by the top European Union court related to the data transfer of Facebook’s EU users to servers in the United States, said Ireland’s regulator.

The social media giant has also been given orders to stop transferring user data across the Atlantic by October.

Why is Facebook being fined?

According to Ireland’s Data Protection Commission (DPC), which acts on behalf of the EU, the social media giant failedto heed a top court warning aimed at protecting users’ data from the security services in the USonce it’s shipped to servers across the Atlantic.

The commission also alleged that Meta continued data transfers to the US without addressing “the risks to the fundamental rights and freedoms” of people whose data was being transferred to the US. The DPC had been investigating Meta Ireland’s transfer of personal data from the EU to the US since 2020.

The social media giant was given five months to “suspend any future transfer of personal data to the US” and six months to stop “the unlawful processing, including storage, in the US” of transferred personal EU data.

EU about the fine on Meta

The supposed privacy breach has prompted the largest fine “ever” under the EU’s General Data Protection Regulation (GDPR), said the European Data Protection Board (EDPB).

The European Data Protection Board (EDPB) chair Andrea Jelinek following the announcement said, Meta’s breach is “very serious since it concerns transfers that are systematic, repetitive and continuous.”

Jelinek also said that since Facebook has millions of users in Europe “the volume of personal data transferred is massive. The unprecedented fine is a strong signal to organizations that serious infringements have far-reaching consequences.”

The announcement also coincides with the fifth anniversary of the GDPR which is seen as the world’s benchmark for privacy.The penalty doled out for Meta surpassed the highest previous record fine imposed by the EU for Amazon $821 million (746 million euros).

This comes after Amazon was forced to pay a fine of the previously mentioned amount by Luxembourg, in 2021 for similarly flouting the EU’s privacy standards.

Meta reacts to announcement

Meta following the announcement of the fine, on Monday, said it would appeal the decision, including the “unjustified and unnecessary fine,” and seek a stay of the orders through the courts.

Meta president of global affairs Nick Clegg and chief legal officer Jennifer Newstead said the company was “disappointed to have been singled out,” and called the ruling “flawed”. Meta’s representatives also warned that the ruling sets a “dangerous precedent for the countless other companies”.

They added, “There is no immediate disruption to Facebook in Europe.”

The company which also owns WhatsApp and Instagram had also previously warned that suspending data transfers on the basis of (SCCs) could have “a far-reaching effect on businesses that rely on SCCs (Facebook and other tech giants) and on the online services many people and businesses rely on”.

Earlier this year, Meta reiterated that without SCCs or “other alternative means of data transfers” it would “likely” not be able to offer access to social media platforms like Facebook and Instagram, across Europe.

DCP’s authority questioned

As per AFP, the Irish regulators only wanted to force Meta to suspend the offending data transfers and that the fine would “exceed the extent of powers that could be described as being ‘appropriate, proportionate and necessary’”. However, their EU counterpart, Concerned Supervisory Authorities (CSAs), disagreed and said, “All four CSAs took the view that Meta Ireland should be subject to an administrative fine.”

Since there was no consensus the matter was sent to the EDPB who ruled that Meta should not only stop the transfers but also pay the record amount of fine. Notably, this is the third fine imposed by the EU on Meta this year and the fourth one in the past six months.

Clegg and Newstead said the EDPB decision to overrule the DPC “raises serious questions,” adding that the US has done more than any other country to comply with EU’s standards and “their latest reforms, while transfers continue largely unchallenged to countries such as China.”

This comes as EU regulators back in December unveiled proposals to replace the previous “Privacy Shield” pact that had been rejected by the EU’s top court. This led to months of negotiations ending with US President Joe Biden’s executive order assuring EU citizens’ data is safe once it’s shipped across the Atlantic.

Why now?

The decision follows revelations by Edward Snowden, the former US National Security Agency contractor back in 2013 and a legal challenge brought by an Austrian privacy campaigner, Max Schrems.

Schrems has expressed concerns that European users’ data is not sufficiently protected from US’ intelligence agencies after Snowden disclosed that officials across the Atlantic have repeatedly accessed people’s information via tech companies like Facebook, Google, and so on.

Notably, Scherms’ lawsuit began a decade-long legal battle over the legality of transferring EU data to the US. According to Reuters, EU regulators led by Ireland’s Data Protection Commissioner Helen Dixon have also been in the midst of finalising the ban on a legal tool used by Facebook to transfer European user data.

This comes as the Irish DPC was given one month, back in April to chalk out the details of the order to block Facebook’s transatlantic data flows, as per which, the ban would take place sometime in mid-May, reported Reuters.

Europe’s highest court, the Court of Justice of the European Union (CJEU), also ruled in 2020 and repeatedly said that an agreement between the EU-US for data transfer was invalid and concluded that Washington does not have sufficient systems in place to protect European data.

However, the judges at the time did not strike down an alternative tool based on contractual clauses but prompted the Irish authorities to issue a preliminary order stating that Facebook can no longer move data to the US via this other method either.

(With inputs from agencies)

WATCH WION LIVE HERE

You can now write for wionews.com and be a part of the community. Share your stories and opinions with us here.